Documentation · Version 1.0

Turnstile setup

Configure merchant-owned Cloudflare Turnstile keys and verify health.

Free version 1.0.0 is available from the official WordPress.org Plugin Directory. Premium plans and downloads are available from the pricing page.

Configure

  • Create a Turnstile widget in the merchant's Cloudflare account
  • Add the checkout hostnames to that widget
  • Choose Cloudflare Turnstile in Settings and enter the site and secret keys
  • Save and use the built-in verification action before relying on it

Data boundary

The widget loads only on a challenged checkout. Server verification sends the response token and merchant secret to Cloudflare, omits the optional shopper IP, and sends no payment details. Turnstile can be used without placing the entire site behind Cloudflare.

Related resources

How the decision flow works · Compatibility matrix · Support · Public source

Version 1.0.0 · Available on WordPress.org

Put a control between checkout abuse and your payment gateway.

Install the complete Free edition from the official WordPress.org Plugin Directory. New installations begin safely in Observe Mode.